Submissions

No Date Request Urls Hosts IDS Rule Score Zero VT Player Etc
1786 2024-07-31 09:12 3.lnk  

0a68f0e0832154a0a4fbdc304392693f


Generic Malware Antivirus AntiDebug AntiVM Lnk Format GIF Format VirusTotal Malware powershell suspicious privilege Code Injection Check memory Checks debugger Creates shortcut unpack itself powershell.exe wrote suspicious process WriteConsoleW Windows ComputerName Cryptographic key
1 4.6 8 ZeroCERT

1787 2024-07-31 09:12 2.lnk  

2ac86d33add8cc3fc0bacb12d028faff


Generic Malware Antivirus AntiDebug AntiVM Lnk Format GIF Format VirusTotal Malware powershell suspicious privilege Code Injection Check memory Checks debugger Creates shortcut unpack itself powershell.exe wrote suspicious process WriteConsoleW Windows ComputerName Cryptographic key
1 4.8 16 ZeroCERT

1788 2024-07-31 07:38 sand.exe  

037f916ac94fcc198a7253a0daf62777


Amadey Gen1 RedLine stealer RedlineStealer Generic Malware EnigmaProtector UPX Malicious Library Admin Tool (Sysinternals etc ...) Malicious Packer .NET framework(MSIL) Anti_VM PE File PE32 DLL PE64 OS Processor Check .NET EXE ZIP Format ftp Malware download Amadey Malware AutoRuns Code Injection Malicious Traffic Check memory Checks debugger Creates executable files ICMP traffic unpack itself Checks Bios Detects VMWare AppData folder VMware anti-virtualization Tofsee Windows ComputerName DNS Cryptographic key crashed
8 5 10 6 15.8 M ZeroCERT

1789 2024-07-31 07:32 postbox.exe  

c53bb047b93851b66fead144d7c46ff3


Gen1 Generic Malware Malicious Library Malicious Packer UPX DllRegisterServer dll PE File PE64 MSOffice File OS Processor Check
M ZeroCERT

1790 2024-07-31 07:28 UXSNUWNZ.exe  

532d05ffeadbd71ebd3427d829a6759f


Generic Malware Malicious Library UPX Malicious Packer PE File PE32 DLL PE64 OS Processor Check PNG Format Check memory Checks debugger Creates executable files unpack itself AppData folder AntiVM_Disk VM Disk Size Check ComputerName
3.2 ZeroCERT

1791 2024-07-31 07:28 random.exe  

9cccb9b47686e3ab460cbee74196ba25


EnigmaProtector PE File PE32 unpack itself ComputerName crashed
1.4 ZeroCERT

1792 2024-07-31 07:27 stealc_valenciga.exe  

3c18dac89d980c0102252ad706634952


Gen1 Generic Malware Malicious Library Admin Tool (Sysinternals etc ...) Antivirus UPX Malicious Packer PE File PE32 DLL OS Processor Check Browser Info Stealer Malware download Vidar Malware c&c Malicious Traffic Check memory Creates executable files unpack itself Collect installed applications sandbox evasion anti-virtualization installed browsers check Stealc Stealer Windows Browser ComputerName DNS plugin
9 1 15 6.0 ZeroCERT

1793 2024-07-31 07:22 Major_0x00012BD4C3BDF0.exe  

c7ea74a05e864d4d67a2fba6be3bb667


Generic Malware Malicious Library Admin Tool (Sysinternals etc ...) UPX PE File PE64 OS Processor Check crashed
0.2 ZeroCERT

1794 2024-07-30 13:57 ms2.bin_dec.dll  

81e9262f4a1fb09caf782d12339c4b9d


Generic Malware task schedule Malicious Library Malicious Packer UPX ScreenShot PWS DNS KeyLogger AntiDebug AntiVM PE File DLL PE64 OS Processor Check VirusTotal Malware AutoRuns MachineGuid Code Injection Check memory Checks debugger buffers extracted Creates executable files unpack itself Windows Remote Code Execution
1 9.4 36 ZeroCERT

1795 2024-07-30 13:55 BITHUMB_20240729.docx.lnk  

2afb9ccd85ffcef656eefc18150741ab


Generic Malware Antivirus AntiDebug AntiVM Lnk Format GIF Format VirusTotal Malware powershell suspicious privilege Code Injection Check memory Checks debugger Creates shortcut RWX flags setting unpack itself Windows utilities powershell.exe wrote suspicious process WriteConsoleW Windows Java ComputerName Cryptographic key
7.2 14 ZeroCERT

1796 2024-07-30 13:40 Authenticator.exe  

dae181fa127103fdc4ee4bf67117ecfb


Emotet Malicious Library Admin Tool (Sysinternals etc ...) UPX PE File PE64 MZP Format OS Processor Check VirusTotal Malware unpack itself
1.6 35 ZeroCERT

1797 2024-07-30 13:38 HostelCurves.exe  

9512f65eed44bccd7da4ca3d8adb397d


Generic Malware Suspicious_Script_Bin Downloader Malicious Library UPX Create Service Socket DGA Http API ScreenShot Escalate priviledges Steal credential PWS Hijack Network Sniff Audio HTTP DNS Code injection Internet API persistence FTP KeyLogger P2P An VirusTotal Malware suspicious privilege Code Injection Check memory Checks debugger WMI Creates executable files unpack itself Windows utilities suspicious process AppData folder malicious URLs WriteConsoleW Windows ComputerName
7.2 M 47 ZeroCERT

1798 2024-07-30 10:13 mobile_kadw.ps1  

563d96353e5b51fdb7fe7509967f9747


Generic Malware Antivirus VirusTotal Malware Check memory unpack itself WriteConsoleW Windows Cryptographic key
1.6 10 ZeroCERT

1799 2024-07-30 10:11 doc.exe  

8f92f52bffea35771a435d8d0ac04b0d


UPX PE File PE64 OS Processor Check VirusTotal Malware PDB
0.8 M 14 ZeroCERT

1800 2024-07-30 10:11 ccxzse.ps1  

2c41269583d28c932670429c40247c3e


Generic Malware Antivirus VirusTotal Malware Check memory unpack itself WriteConsoleW Windows Cryptographic key
1.6 M 13 ZeroCERT